Short answer
There is no legal way to sell CVV numbers online in exchange for Bitcoin in the United States. A CVV is part of an access device under federal law. Selling one, buying one, or holding fifteen or more of them with intent to defraud is a felony under 18 U.S.C. § 1029. Bitcoin is not a shield. Federal prosecutors charge these cases as access device fraud, wire fraud, and identity theft.
What a CVV is
A CVV is a three or four digit code printed on a payment card. CVV2 and CVC2 are the codes on the back of Visa and Mastercard products. Card networks use the code to check that the person entering card data has the card in hand during a card-not-present purchase. The code is not written to the magnetic stripe or the EMV chip. Under the PCI Data Security Standard, it is classified as sensitive authentication data.
Federal statutes that apply
- 18 U.S.C. § 1029. Covers producing, selling, transferring, and possessing access devices. Subsection (a)(2) reaches trafficking in unauthorized access devices. Subsection (a)(3) reaches possession of fifteen or more unauthorized access devices. Most violations carry up to 10 years in prison, and up to 15 years for certain factors.
- 18 U.S.C. § 1343. Wire fraud. Applies when the internet or another interstate wire is used to run the scheme. Up to 20 years.
- 18 U.S.C. § 1028A. Aggravated identity theft. Adds a mandatory 2-year term that runs consecutively to the underlying sentence.
- 18 U.S.C. § 1956 and § 1957. Money laundering. Applies to moving proceeds through Bitcoin and other convertible virtual currency.
Bitcoin tracing
FinCEN treats convertible virtual currency exchangers as money transmitters under 31 CFR 1010.100(ff). Exchanges that serve US customers must register, keep records, and file suspicious activity reports. Blockchain analysis firms group addresses into clusters and score them for ties to known fraud. A payment in Bitcoin leaves a public ledger entry that stays in place after the sale. Court records in access device cases list wallet addresses and exchange records as evidence.
Card network and PCI rules
PCI DSS Requirement 3 prohibits storage of sensitive authentication data after authorization. A merchant or processor that keeps CVV data in a database is out of compliance, and card networks can fine the acquirer. This is one reason a stolen CVV has a short working life. The code can be used, and the issuing bank can void the card once a fraud report arrives.
Consumer liability limits
Under the Fair Credit Billing Act (15 U.S.C. § 1643) and Regulation Z (12 CFR 1026.12), a cardholder's liability for unauthorized credit card charges is capped at $50. The issuer absorbs the rest. That cost drives bank investigations, chargeback rules, and referrals to the FBI and the Secret Service.
Marketplace takedowns
Dark web markets that list card data have a short record. In 2017, US and European authorities seized AlphaBay and Hansa Market. In 2022, German authorities seized the servers behind Hydra Market. Each seizure produced transaction records that supported later indictments.
If your card data is offered for sale
- Call the card issuer and ask for a new card number. Do not wait for a fraudulent charge to appear.
- Review statements for small test charges, which often come before a large one.
- File a report at the FTC Identity Theft site and keep the report number.
- File a complaint with the FBI Internet Crime Complaint Center.
- Place a free credit freeze with each of the three major credit bureaus.
What is not covered here
This page does not list markets, prices, payment methods, or steps for buying or selling card data. That conduct is the subject of the statutes above, and no part of it is lawful in the US.